As cited
Copy frozen at (site build).
threat intel
FBI raises alarm over deceptive phishing campaign targeting prominent people
The FBI has issued a warning about a sophisticated phishing campaign that has been active since late 2025, targeting high-profile individuals and their associates through commercial messaging applications. Attackers use social engineering to trick victims into granting OAuth consent to malicious applications impersonating legitimate cloud services like Microsoft and Google, giving the threat actors persistent access to email, files, and other sensitive data that cannot be revoked by changing passwords. The attackers have impersonated government officials, journalists, and public figures, and bypass both passwords and multifactor authentication (MFA) through this consent phishing technique.
Why it matters: High-profile individuals, their family members, and business associates face account compromise and data theft; all practitioners should educate users that approving OAuth requests from unfamiliar senders grants persistent access that MFA does not block and can only be revoked through security settings.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
FBI raises alarm over deceptive phishing campaign targeting prominent people
The FBI has issued a warning about a sophisticated phishing campaign that has been active since late 2025, targeting high-profile individuals and their associates through commercial messaging applications. Attackers use social engineering to trick victims into granting OAuth consent to malicious applications impersonating legitimate cloud services like Microsoft and Google, giving the threat actors persistent access to email, files, and other sensitive data that cannot be revoked by changing passwords. The attackers have impersonated government officials, journalists, and public figures, and bypass both passwords and multifactor authentication (MFA) through this consent phishing technique.
Why it matters: High-profile individuals, their family members, and business associates face account compromise and data theft; all practitioners should educate users that approving OAuth requests from unfamiliar senders grants persistent access that MFA does not block and can only be revoked through security settings.
- Source published
- First seen by Cybersecurity Tracker